True random numbers from amplified quantum vacuum

Random numbers are essential for applications ranging from secure communications to numerical simulation and quantitative finance. Algorithms can rapidly produce pseudo-random outcomes, series of numbers that mimic most properties of true random numbers while quantum random number generators (QRNGs) exploit intrinsic quantum randomness to produce true random numbers. Single-photon QRNGs are conceptually simple but produce few random bits per detection. In contrast, vacuum fluctuations are a vast resource for QRNGs: they are broad-band and thus can encode many random bits per second. Direct recording of vacuum fluctuations is possible, but requires shot-noise-limited detectors, at the cost of bandwidth. We demonstrate efficient conversion of vacuum fluctuations to true random bits using optical amplification of vacuum and interferometry. Using commercially-available optical components we demonstrate a QRNG at a bit rate of 1.11 Gbps. The proposed scheme has the potential to be extended to 10 Gbps and even up to 100 Gbps by taking advantage of high speed modulation sources and detectors for optical fiber telecommunication devices.


Introduction
The need for random numbers in research and technology was recognized very early [1], and has motivated electronic and photonic advances [2][3][4]. Random numbers support critical activities in advanced economies, including secure communications [5][6][7], numerical simulation [8] and quantitative finance [9]. For this reason, there has been intense effort to develop practical true random number generators, to replace existing pseudo-random methods. QRNGs employ a true source of randomness known to science, the randomness embedded into quantum physics. Recently, it has been shown that quantum physics also can be used to verify the randomness of entanglement-based generators [10,11].
Although any quantum measurement provides some randomness, a practical source must be simultaneously fast, inexpensive, and robust. For this purpose, fluctuations of the quantum vacuum are very attractive because the electric field amplitude is a continuous quantity, a single measurement can yield many true random bits. True vacuum is also perfectly white, uncorrelated, and broadband; the quantum field renews its random value arbitrarily quickly. Guaranteeing true vacuum is far from trivial, however; any scattered light will contribute a non-random component to the field measurement. Here we demonstrate extraction of random bits from vacuum using optical amplification. Homodyne detection based schemes [19,20,24] guarantee that the signals originate in vacuum noise. Our method relies on the vacuum noise fluctuations as homodyne detection schemes, and at the same time achieves high bandwidth, because the requirement for shot-noise-limited detection is removed.
Relative to demonstrated methods for QRNG and achieved speeds, our proposed device is not only highly integrated, using commercially available components, but also has other advantages. In particular, the strong current modulation, well above and below threshold, ensures true randomness from vacuum. This active gain control allows a single device to have both a short coherence time, for rapid extraction of uncorrelated random bits, and a high signal level. In this way, standard photodiodes can be used. Furthermore, due to the high power of the signal pulses, the signal-to-noise ratio (SNR) is high. Hence, several random bits per detection event can be generated, limited by the classical noise of the measurement equipment. To our knowledge, it is the first time that our use of current gain modulation is used in QRNG.

Device operation
We use a distributed feedback (DFB) laser diode (LD) as the oscillator, providing single-mode operation and high modulation bandwidth. The DFB LD is directly modulated at around 100 MHz by a train of ∼ 1 ns electrical pulses, as shown in Fig. 1(a). A polarization-maintaining, all-fiber unbalanced Mach-Zehnder interferometer (MZI) with a relative delay of t loop ≈ 10 ns provides stable single-mode operation of the interferometer, as shown in Fig. 1(b).
The LD is set with 25 mA DC bias current, far below its threshold value of 36 mA. Phase-randomized coherent optical pulses of 400 ps time width and 3.5 mW peak power are produced. A 30 dB optical isolator (OI) is placed just after  the LD to avoid back reflections into the oscillator cavity. Then, the linearly polarized optical pulses are split in power using a polarization maintaining coupler (PMC) with a fixed coupling ratio. In one of the output ports of the PMC, a 2 m polarization maintaining fiber (PMF) patchcord is connected, which corresponds approximately to the equivalent length of the PRF. Both arms of the interferometer are connected to a second PMC where the interference between pulses takes place. The overall interferometer setup, at the output, has power coupling ratios of T 2 12 ≈ 49.8% and R 2 12 ≈ 40.3%, and polarization isolation of 23.98 dB and 25.23 dB for the two arms. At one of the output ports of the interferometer, a 150 MHz photodiode is connected to collect the different interfering optical pulses which are processed by a fast oscilloscope. The oscilloscope is operated with a 200 MHz bandwidth for the input channel, triggered by the system clock reference.
The path delay difference of the interferometer can be adjusted to temporally overlap subsequent pulses. On the one hand, the time delay between interfering pulses can be controlled by fine tunning the propagation properties of the long arm of the interferometer to change the parameter φ loop . For instance, by changing the temperature of the optical fiber one can produce a refractive index change and also thermal expansion of a wavelength for a 0.03 • C temperature change, corresponding to 4.25 fs. Albeit, the time adjustment range achievable is limited compared to the pulse repetition period ∼ 10 ns. On the other hand, the interferometer can be temperature stabilized to 0.01 • C to keep the parameter φ loop and the PRF changed to increase or decrease the time between successive pulses. The time delay difference between both arms of the MZI is related to the PRF as ∆t = 1/PRF, which allows an accurate and larger time adjustment range. The path delay difference of the interferometer was adjusted by setting the PRF at 97.6 MHz.

Laser physics analysis
The method operates on the field within a single mode of a semiconductor diode laser. As shown in Fig. 2, the laser is first operated far below threshold, producing simultaneously strong attenuation of the cavity field and input of amplified spontaneous emission (ASE). This attenuates to a negligible level any prior coherence, while the ASE, itself a product of vacuum fluctuations, contributes a masking field with a true random phase. The laser is then briefly taken above threshold, to rapidly amplify the cavity field to a macroscopic level. The amplification is electrically-pumped and thus phase-independent. Due to gain saturation, the resulting field has a predictable amplitude but a true random phase. The cycle is repeated, producing a stream of phase-randomized, nearly identical optical pulses. As shown in Fig. 1(b), interference of subsequent pulses converts the phase randomness into a stream of pulses with random energies, which is directly detected and digitized.
During the attenuation phase, the cavity field is described by the Langevin  The LD is first taken below threshold, to attenuate the cavity field to a weak thermal state (in red), independent of its previous value (in blue). (b) The LD is then taken above threshold, so that phase-insensitive amplification brings the field amplitude |α| to a level fixed by saturation, while the phase retains the random thermal-state value.
where a is the field operator for the mode, ω is its angular frequency, γ is the (energy) decay rate and Γ = γ 1/2 a res + Γ ASE is a noise operator, with a res a reservoir mode. The first term is from attenuation [25], and the second from ASE. We can estimate γ = γ cav + γ mat as follows: The cavity contribution is γ cav = −c ln(R)/(2nL) = 5 × 10 10 s −1 , where c is the speed of light in vacuum, R = 0.3 is the out-coupler reflectivity, n = 3.6 is the refractive index, and L = 300µm is the cavity length. The material contribution γ mat ranges from cα/n ≈ 10 11 s −1 at zero current to γ mat = −γ cav at threshold. Here α ≈ 10 4 cm −1 is the intrinsic absorption of GaAs at 852nm [26]. Interpolating, at 70% threshold current, we obtain γ ≈ 10 11 s −1 , or about 400 dB/ns. This renders completely negligible any prior coherence in the cavity, and the remaining field is an equilibrium between ASE and attenuation. The phase of this field is a true quantum random variable, its value determined by ASE which is driven by vacuum fluctuations. When the laser is taken above threshold, the equilibrated field is amplified, limited by gain depletion [27], to produce observed output powers of P ≈ 3.5 mW or 1.5 × 10 7 photons/ns, with about P/γ cav ≈ 3 × 10 5 photons in the cavity. The amplification is phase-insensitive, and the phase of the cavity field remains truly random.
Considering the speed limits of this technique, we note that even at a modulation rate of 20 GHz, i.e., an attenuation time of ∼ 0.25 ns, the attenuation is 100 dB. The field contribution remaining from the previous pulse is 3 × 10 −5 photons, or ≈ 15 bits below the vacuum fluctuations. The physics of the process can thus support QRNG rates in excess of 100 Gbps.

Characterization of the coherence of the laser pulses
The interferometric setup allows us to determine the first order coherence properties of the laser pulses, described by the correlation functions G(τ ) ≡ dt Ê (−) (t)Ê (+) (t + τ ) , or its normalized version g(τ ) ≡ G(τ )/G(0). HereÊ (±) are the positive-and negative-frequency parts of the emitted fieldÊ and integrals are taken over the duration of the pulse. We expect the pulse energies G(0) to be narrowly distributed, and g(t rep ) to have near-unit magnitude and random phase, where t rep corresponds to the time between successive pulses given by the pulse repetition frequency (PRF), as subsequent pulses have very similar envelopes and random phases φ. The interferometer output isÊ out (t) = T 12Ê (t) + R 12Ê (t + t loop ) where T 12 , R 12 indicate combined transmission and reflection coefficients through the two beamsplitters. If we define the pulse energy in both arms of the interferometer as u i ≡ R 2 12 G(0) and v i+1 ≡ T 2 12 G(0), the energy at the output port of the interferometer, u where φ loop = ωt loop is the phase introduced by the delay loop. We measure the relevant statistics as follows (data shown in Fig. 3(a)): narrow distributions of u i and v i+1 are directly observed by blocking one or the other path. Interference leads to a broadening of the observed distribution, with the broadest distribution corresponding to t rep = t loop . From the width of the u (out) i distribution and the mean values of u i , v i+1 , we can estimate the interference visibility |g(t loop )| ≈ 90.22%. To demonstrate that the laser pulses are phase-uncorrelated, we collect statistics both for φ loop fixed, and for φ loop swept over several π, obtained by heating the fiber loop during acquisition. Results, shown in Fig. 3(b), are statistically identical, indicating the absence of any phase relation between subsequent pulses.

Statistical testing
The output of the PIN photodiode was highpass filtered with a cutoff frequency of 40 MHz and digitized using the waveform integration function of an oscilloscope with input bandwidth 200 MHz, sampling speed of 2.5 Gsps and a 12-bit analog-to-digital converter (ADC). The 10 ns time range setting, compliant with the PRF, and sampling speed of the oscilloscope permits to acquire 25 samples over a pulse. The oscilloscope translates the multiple samples per pulse to a single measurement. The nearly uniform distribution of observed energies permits   the use of equally-sized encoding bins, and facilitates calibration. Records of 10 6 output pulses were collected in order to characterize the statistical correlations of the acquired raw data and to determine the number of extractable random bits per pulse. The normalized correlation of successive samples as a function of sample delay of the raw data is computed as the modulo-N circular autocorrelation for finite length sequences and it is normalized to the maximum, shown in Fig. 4(a). The correlation of data samples follows a delta-function like behavior which indicates a random sequence with low impact of drifts in the system. The quantum random bit content of the recorded signal is determined as follows: The pulse distribution of Fig. 3 is divided into 2 b equally-sized bins and the Shannon entropy is calculated. As shown in Fig. 4(b), the entropy increases linearly with b, up to the value b = 12, where it saturates to 11.8 bits of entropy. The same procedure, applied to the detection noise, finds the classical noise entropy. Subtracting the noise entropy, the quantum optical noise contribution reaches a level of 11.1 bits per pulse at b = 12. Multiple samples per pulse achieves larger accuracy when used together with higher resolution ADC. This allows to better bound the contribution of the classical noise and thus permits to extract more true random bits per pulse.
The observed classical noise, however random it may appear, could in principle be the result of a completely predictable process. Indeed, randomness tests (described below) detect patterns in the recorded classical noise. To completely remove these patterns, we first note that the entropy of the classical noise places an upper bound on the information it can contain. We then remove this quantity   The correlation data samples follows a delta-function like behavior indicating a random sequence. (b) Total entropy, calculated from the measured distribution shown in Fig. 3. Distribution is divided into 2 b bins, from which the Shannon entropy is calculated. Optical contribution, up to 11.1 bits per pulse, is found by subtracting entropy of the measured electronic noise.
of information, using cryptographic hash functions, from the combined quantum and classical noise [19]. We use the Whirlpool hash function [28]; other standard randomness extractors could have also been employed [29,30]. These cryptographic functions mix the input data bits, increasing the theoretically secure entropy per bit at the cost of losing output bits. The reduction factor of the hash function applied to the collected raw bits is 1.08. As a result, we obtain that the random bit generation rate of the current device accounts to 1.11 Gbps.
We have performed all tests of randomness from TestU01 [31]. Considering the optical pulse data set, some test fail when applied to the raw data set, while they were successfully passed when applied to the hashed data set. Confirming that the hashing removes any remaining predictable behavior and increases the entropy per bit. Instead, the classical noise data set fails some tests both before and after hashing, using the same hashing factor.

Conclusions
In conclusion, we have demonstrated high-bandwidth extraction of random bits from quantum vacuum fluctuations using optical amplification. The use of strong attenuation followed by amplification guarantees that the signal originate from quantum noise, and provides macroscopic signals compatible with the highest bandwidth detection. With commercially-available components, we demonstrate over 1 Gbps true random number generation. The QRNG device is low power consumption, robust, and can be easily automated allowing it to have a long operational lifetime. Consideration of the laser physics indicates that rates above 10 Gbps and even 100 Gbps are possible. The high random numbers generation rate extends the practical applications of our method to erode the dominance of currently used classical RNG choices. The method can be applied to high speed secure communication, to the gambling industry and to cryptography.